3GPP Security Specifications

5G Security & Protocol Reference Library — Interactive Index
31
Documents
14
Product Classes
50+
Test Cases
17
Threat Categories
Architecture, Threats & Methodology

TS 33.501

Architecture

5G Security Architecture and Procedures — master security spec covering key hierarchy, authentication (5G-AKA/EAP-AKA'), SBA security, SEPP, slicing, GTP-U

TR 33.926

Threat Catalogue

Threats and Critical Assets — defines all threat categories (§5.3.1-§5.3.8) including GTP traffic isolation, SBI threats, and risk assessment mapping

TS 33.210

NDS/IPsec

Network Domain Security — IPsec/IKEv2 requirements, ESP tunnel mode, cipher suites, GTP over IPsec per interface

TS 33.310

PKI / Certificates

NDS Authentication Framework — PKI architecture, certificate profiles for TLS/IPsec/SEPP, CMPv2/EST enrollment, revocation

TR 33.916

Methodology

SECAM — Security Assurance Methodology for evaluation process, accreditation of test labs, NESAS relationship

Baseline SCAS

TS 33.117

General SCAS (Baseline)

Catalogue of General Security Assurance Requirements — ALL product classes must pass these tests: SBA/SBI, technical baseline, OS/web hardening, GTP-C/GTP-U filtering, vulnerability testing

Product Class SCAS

TS 33.512

gNB SCAS

RAN base station — physical security, key handling, N2/N3 IPsec, GTP-U handling, RRC security

TS 33.513

UPF SCAS

User Plane Function — GTP-U filtering (TEID validation, GTP-in-GTP), PFCP N4 security, N6 protection, traffic separation

TS 33.514

UDM SCAS

Unified Data Management — subscriber key protection, auth vector security, SUPI/SUCI privacy, SBI auth

TS 33.515

AMF SCAS

Access & Mobility Management — NAS security mode, bidding-down prevention, N2/NGAP security, registration

TS 33.516

AUSF SCAS

Authentication Server — 5G-AKA/EAP-AKA' protocol handling, K_AUSF protection, SBI security

TS 33.517

SEAF SCAS

Security Anchor Function — K_SEAF/K_AMF key derivation, ABBA anti-bidding-down validation

TS 33.518

SMF SCAS

Session Management — PFCP/N4 security, PDU session authorization, UP security policy enforcement

TS 33.519

NEF SCAS

Network Exposure Function — external API auth, SUPI privacy, input validation, rate limiting

TS 33.521

NRF SCAS

Network Repository Function — NF registration auth, OAuth 2.0 token issuance, discovery authorization

TS 33.522

SEPP SCAS

Security Edge Protection Proxy — N32-c TLS, N32-f PRINS (JWS/JWE), inter-PLMN certificate management

TS 33.520

PCF SCAS

Policy Control Function — QoS policy enforcement, N5/N7/N15 security, charging bypass prevention

TS 33.527

SCP SCAS

Service Communication Proxy — Model C/D routing, token handling, traffic inspection prevention

TS 33.511

ng-eNB SCAS

Next-generation eNodeB — N2/N3/Xn/X2/Uu security, rogue base station prevention, physical security

Protocol Specifications

TS 29.281

GTPv1-U

GTP User Plane — header format, extension headers (PDU Session Container 0x85), TEID management, 5G N3/N9 tunneling

TS 29.274

GTPv2-C

GTP Control Plane — session management, bearer operations, S11/S5/S8 signaling, 12-byte header, Information Elements

TS 29.244

PFCP (N4)

Packet Forwarding Control Protocol — SMF-UPF signaling, PDR/FAR/QER/URR rules, session establishment, 64-bit SEID

TS 29.500

SBI Framework

5G Service-Based Interface — HTTP/2 transport, NRF discovery, OAuth 2.0 authorization, SCP communication models

Security Architecture

TS 33.401

EPS Security

EPS Security Architecture — EPS-AKA, key hierarchy (K→K_ASME→KeNB), NAS/AS security, GTP per-interface protection

TS 33.402

Non-3GPP Access

Non-3GPP Access Security — WiFi/ePDG/N3IWF, EAP-AKA', IKEv2 tunneling, trusted/untrusted access architectures

Security Features

TS 33.535

AKMA

Application Key Management Architecture — AAnF, K_AKMA→K_AF derivation, application-level authentication via 3GPP credentials

TS 33.536

MBS Security

Multicast/Broadcast Security — MB-SMF/MB-UPF, MSK/MTK key management, N3mb GTP-U multicast

Security Studies (TRs)

TR 33.899

5G Threat Study

Study on 5G Security Aspects — 21 key issues covering authentication, SBA, slicing, privacy, IoT that shaped TS 33.501

TR 33.809

False Base Stations

Study on False Base Station threats — IMSI catching, bidding-down, MITM relay, 5G protections and remaining gaps

TR 33.818

UPF Security

Study on UPF Security — edge/MEC deployment, N3/N4/N6/N9 interface threats, multi-cloud and enterprise scenarios

TR 33.848

Virtualization Security

Study on NFV/Container Security — hypervisor, K8s, MANO threats, NF-specific virtualization concerns

5GS Architecture (23-Series)

TS 23.501

5GS Architecture

5G System Architecture — NF definitions, reference points, SBI model, network slicing (S-NSSAI), QoS framework (5QI)

TS 23.502

5GS Procedures

5G System Procedures — registration, authentication, PDU session management, handover, deregistration flows

Cross-Reference Matrix

Which specs reference which — showing key dependencies across the full library

Document 23.50123.50229.24429.27429.28129.500 33.11733.21033.31033.40133.50133.926
23.501—✓···✓····✓·
23.502✓—✓✓✓✓····✓·
29.244✓✓—·······✓·
29.274·✓·—✓··✓·✓✓·
29.281✓✓·✓—··✓··✓·
29.500✓✓···—··✓·✓·
33.117······—✓✓·✓✓
33.210···✓✓·✓—✓✓✓·
33.310·····✓✓✓—·✓·
33.401···✓✓··✓✓—✓·
33.402·······✓✓✓✓·
33.501✓✓✓✓✓✓✓✓✓✓—✓
33.926······✓···✓—
33.511····✓·✓✓·✓✓✓
33.512····✓·✓✓··✓✓
33.513··✓·✓·✓✓··✓✓
33.514······✓···✓✓
33.515·✓····✓···✓✓
33.516······✓···✓✓
33.518··✓···✓···✓✓
33.519·····✓✓···✓✓
33.520·····✓✓···✓✓
33.521·····✓✓···✓✓
33.522······✓✓✓·✓✓
33.527·····✓✓·✓·✓✓
33.535✓····✓····✓·
33.536✓✓··✓·····✓·
33.809·········✓✓·
33.818✓·✓·✓··✓··✓·
33.848✓·····✓···✓✓
33.899✓✓·✓✓··✓·✓✓·
33.916······✓···✓✓